Authorization header of every request:
401 Unauthorized.
Get an API key
Create keys in the dashboard under Settings → API Keys. You need thedeveloper role or higher.
- The full key is shown once, when you create it. Save it right away.
- You cannot see a key again later. You can only revoke it and create a new one.
- Each key belongs to one workspace. It can only see and change that workspace’s agents, calls and data.
Keep your key on the server
An API key has no scopes. Any key can do everything in its workspace. It can delete agents, place phone calls that cost money, and read every transcript. There are no read-only keys and no per-agent keys. So treat the key like a password:- Store it in an environment variable or a secret manager on your server.
- Never put it in browser code, a mobile app, or a
NEXT_PUBLIC_variable. - Never commit it to a repository.
Session tokens for the browser
To start a web session, your server callsPOST /api/v1/realtime/sessions with the API key. The response has a session_token and a ws_url. It is safe to send these to the browser because the token:
- expires after 60 seconds
- works for one connection only
- only works for one agent and one
user_id
Managing keys through the API
The key endpoints (POST /api/v1/keys, GET /api/v1/keys and DELETE /api/v1/keys/{key_id}) do not accept an API key. They need a dashboard login session instead: